A token is a way in without the sign-in screen. The yore command uses one, and so can an MCP client or a script of your own that doesn't sign in with OAuth.
Create a token
- Sign in and open Agents.
- Under Tokens, choose Create token and name it after where it will live, like yore on my laptop.
- Copy the token right away. It's shown once: Yore only keeps a hash of it.
A token lasts one year from the day you create it.
Use a token
For the command:
yore login
For anything else, send it in the Authorization header. The same token opens the MCP server and the API the site and the command ask:
curl -H "Authorization: Bearer YOUR_TOKEN" -H "Accept: application/json" https://yore.steddle.com/api/v1
The limit is the same as over OAuth: 120 requests per minute per account.
Keep it safe
A token acts as you. Whoever holds it can read your plans, start a run, make a share link and delete a plan. So:
- keep a token out of code you share and out of repositories;
- give each machine or client its own token, so you can cut one off without the others;
- revoke a token you don't use.
Revoke a token
The Agents page lists every token with when it was created and when it was last used. Press Revoke next to one and confirm. It stops working at once.